Overview
As a Senior Security Analyst at Monzo, you will help protect our customers by strengthening third‑party and supplier security and guiding risk-based decisions. You’ll work across security, engineering, product, and procurement to translate evidence into practical actions and scalable controls. You’ll lead assurance activities across audits, regulatory reviews, and vendor assessments, balancing security needs with user experience. This is an opportunity to shape a growing security program in a customer‑centric fintech. You’ll make a real impact by turning complex challenges into clear, prioritized outcomes.
Pay / Benefits
- Incentive-based compensation
- Flexible working hours
- Learning budget (£1000 annually)
- Macbook provided
- Work-from-home support
- Remote/hybrid options
Responsibilities
- Deliver third‑party and supplier security assurance, assessing evidence and guiding risk treatment across the supplier lifecycle
- Lead and contribute to control testing, PCI DSS assessments, regulatory reviews, and audits, identifying gaps and driving remediation
- Strengthen governance through practical policies, procedures, and controls
- Support Monzo’s Security Front Door by collaborating with analysts and specialists to improve security inquiries handling
- Own security problems end-to-end, defining the approach and coordinating the right people to deliver outcomes
- Help product and engineering teams build safely by identifying security risks and translating requirements into actionable controls
- Improve workflows using data, automation, and AI to scale security processes
- Raise security capability and knowledge across the team, mentoring others and staying current with industry developments
Key requirements
- Strong understanding of security risk and risk-based decision making
- Experience in third party or supplier security assurance is a plus
- Ability to review supplier questionnaires, security policies, and assessment reports and identify gaps
- Solid security fundamentals, technical curiosity, and comfort with technical detail
- Proactive, independent worker who can manage competing priorities and make informed decisions
- Clear communicator able to explain risks and recommendations to technical and non‑technical audiences
- Collaborative mindset with cross-functional working style and stakeholder relationship building
- Passion for security and ongoing professional development
- experience in regulated environments or audits is a bonus
- familiarity with PCI DSS, ISO 27001, SOC 2 or NIST alignment is a plus
- collaboration
- proactivity
- communication
- security risk assessment
- supplier/security assurance
- PCI DSS
…
